James Hadley on Building Cyber Workforce Resilience at KB4-CON 2026
At KB4-CON 2026, Alan Shimel spoke with James Hadley, founder and CEO of Immersive Labs, about cyber workforce resilience and the importance of preparing people to make better decisions under pressure.
The conversation explores how realistic cyber drills, simulations and skills-based exercises can help teams build confidence, measure readiness and improve their response to real-world threats.
Transcript
Hey everyone, we're back here at KB4 in Orlando. Let me introduce you to our next guest. His name is James Hadley, and he is the founder of Immersive.
James, first of all, welcome. Thank you. I think the last time, did I interview you maybe, was it at RSA?
Or- I think it was three or four years ago now, RSA, yeah. Yeah, it was right after the COVID, right? The first one after COVID, maybe?
I think so, yes. That's my recollection as well. Anyway, it's great to have you back on Techstrong TV.
Glad to be here. Thank you. So James, I'm sure everyone is saying, "Oh yes, I remember that interview.
" Well, maybe not. Let's start from scratch then. Give people a sense of, you're the founder of Immersive.
Let's talk about what led you to be crazy enough to go found a company. Yeah, absolutely. So prior to starting Immersive, I had a background in government and defense organizations working in cybersecurity and research.
I then had an opportunity to become the lead instructor, too, at the GCHQ Cyber School, and that purpose of the cyber school was to identify talent, over a 10-week period. Monday morning, first day, how do you spell cyber? Day 50, reverse engineering malware, customer exploit development.
And it was during that time I identified that cyber moves so quickly, the idea that you do training or upskilling and you're done is bonkers because there's new threat techniques coming out every day, and we can talk more about how that's changing with AI later. And then the most important value proposition was there's so much money spent on policy and tech in cybersecurity, but there's no way of actually knowing or proving if something was to happen tomorrow, would my team be able to recover and respond? So that's why we started the business.
It was how do we upskill people in real hands-on environments and prove they can do the job relevant to cyber as new threats come out on a daily basis, so that customers have confidence in their team, and then they can benchmark it to their peers. And that was how long ago now? Nine years ago.
So a long time. And over that time, you guys have really made your mark in the enterprise market. A large percentage of the business is large enterprises.
Yeah, 30% of the Fortune 100 leverage and trust Immersive today for cyber resilience. And since we last met and over the course of nine years, we've always been expanding our value proposition. So when we started, it was all about how do we upskill people in the blue team, defenders- Yeah ...
but also the offensive team and the red team. Right. But we now do it for developers, cloud engineers, AI engineers, the wider workforce- Right ...
and boards and executives, and even their suppliers through our supply chain capabilities. So this is expanding beyond a niche of the security team into the broader workforce. Yeah, we now cover the entire organization and their supply chain relevant to their role.
So what's fit for purpose for a developer is very different to someone that works in the SOC, which is very different from someone that's running crisis management and comms during potentially a ransomware incident. So it's about exercising the right team and the right modality based on the threats they face to get evidence and proof for their regulators, boards, and insurers that they have a high level of maturity when it comes to cyber resilience. Excellent.
I love it. People out there watching saying, "This sounds like something I might be interested in, or I'd like to dive in more," how do they engage with Immersive? Yeah, so we just generally work with our customers directly in the enterprise space.
com. com. Yeah, and we also work with alliance partners and consultancies as well.
Like service integrators or consultants more? More like consultancies. So imagine the Accentures of the world, IBM, and others, where we have the platform, but sometimes some of the services element around building programs, around those programs are delivered by the services partner.
Yeah. So I've always called them the SIs. Yeah.
The service integrators. Yeah. Yeah.
Got it. com, though, is that website. That's right, yeah.
So look, we talked about blue teams, red teams. A lot of people are wondering, is that even relevant coming forward? Are we moving from an area of finding vulnerabilities being the goal?
Well, we could find as many vulnerabilities as you want, it seems now with AI. How are we responding? Where's the governance?
Where is the response? How is that going to affect remediation, not just patching, but remediation? It seems like our world has changed, right?
Some are calling it the vulnerability apocalypse. Yeah. I don't know if it's an apocalypse, but AI is having a profound impact.
How is that impacting your business? So fortunately for Immersive, AI is a tailwind. I think, prior to RSA this year, people were a bit cautious of what can AI really do in cyber.
And I think obviously the Mythos revelation sort of sped up the change process, and I think it caused some companies to be on the back foot a bit around the sophistication and the speed and consistency of AI and how quickly it's maturing. So we see it across two main camps. So when we speak to our customers today, they have two AI challenges.
One, the organization wants to be able to turn on AI for everyone. Everyone wants to be a builder, use cowork, use GenAI, but they don't have proof that those individuals understand the threats and the risks relevant to their policies. So we in Immersive have a concept of an AI driving license.
So you go through exercises and simulations relevant to the capability you want, and once you've proven you understand it and you can use it securely, you again get the entitlement to have it within your customer environment. So it's gatekeeping access to AI for the use cases around vibe coding, co-agent, GenAI, relevant to the tools like Claude or Copilot. So that's one big challenge that we're solving for our customers.
The second is with agentic, the traditional processes you talked about, vulnerability management, incident response, threat huntingManual processes in a SIEM is not going to keep up, and therefore, organizations will need to invest in agentic SOC capabilities, but have no idea where to start. These are generally people like security analysts now being asked to write engineering and build agents. So we built at Immersive an AI agentic harness, which allows our customers to build and test agents in our platform against our cyber ranges, where we then measure the efficacy of the agent they built and the efficiency relevant to token spend.
Because if you don't get the efficiency right, you can end up costing way more than a traditional SOC analyst through running agents autonomously. And we do that for defensive, offensive, and for developers seeking to remediate vulnerabilities. And a really interesting thing, and you'll hear at KB4 Con today, is about the human in the loop.
So if you think about phishing in the past, well, actually, there's a real risk in the future, especially in large SOCs or MSSPs, where the AI's going to be triaging the threat and making a recommendation, and we might start getting people clicking, "Yeah, I trust the AI," and that might say, "Well, I've hallucinated. " So we've built a process for verifying the human in the loop as it relates to measuring the outcome of the AI, and then the decision to approve. I love it.
So two really must-have things for enterprise companies now. Cyber resilience is still really important. Exercising tabletops- Sure ...
disaster recovery is really important. But the new- I would say it's more important than ever. But it's more important than ever.
Yeah. So we're helping on the cyber resilience part as we always have, but now really leaning in on agentic SOC transformation and AI enablement and entitlement. So the speed at which you've rolled this out leads me to believe that you're using AI to help you do this.
Yeah. We leverage AI internally, so all of our product capabilities now have advanced AI features. So for example, in the past, we would build content around AppSec or CloudSec.
Customers can now use conversational AI to build their own hands-on labs and exercises. So if they're using an obscure coding language that we don't cover, they can do conversational AI, and it will build all the code samples and the hands-on lab for their developers in minutes rather than in the past, weeks a time. I love it.
So that's a big advantage. And if I think even to outcomes that customers want to achieve, no two customers are the same. They have different regulatory needs, different compliance needs, different frameworks.
Sure. So using our AI program builder, they can say, "I, as a security leader, want to achieve these outcomes. I want to improve my mean time to detect, and I use CrowdStrike and Microsoft Sensor," for example.
Our platform will then build that end-to-end program with the reporting relevant to that customer. Love it. I love it.
Now, look, I think it's just human nature that we tend to think the present time is sort of the crest or the apex. But the fact of the matter is, every week brings new revelations and new oh, wow moments. What comes next?
We've seen Mythos. Now, in my opinion, we're going to see Mythos-like capability work its way down the entire life cycle, not just finding vulnerabilities. They're already using it to write exploits, but we're going to use it for remediations.
We're going to use it for testing. Right? There's going to be a pain period, but as a result, I think two years from now, we're actually going to have more secure code, better secure code coming out the other end.
Yeah. What does that mean for Immersive? How do you help that, foster that, ride that, if you will?
Yeah. So customers are always at different stages of maturity on their journey. So we might have some customers who have yet to even turn on AI because they're risk averse, and we have others that are already halfway through an agentic SOC transformation.
So it's about meeting them where they are on their journey. I think for Immersive, our thing has always been around speed. When a new threat goes live, we aim to turn it into an exercise within 24 hours.
We did it with OpenClaw. We had a practical lab within four hours, for example- Sure ... in the platform.
The speed of AI and cyber is now faster than ever, so having that ability to rapidly respond to the market, rapidly respond to the threats, and enable customers in our safe environment, I think is key to then giving them the confidence they can then do it in their production environments. I do think we're going to see this vulnerability trough to start with. I think there's some really interesting unit economics, though.
So for every offensive agent that's running 24 by seven against, say, a financial services organization, that is generating 10X amount of work for the defenders because they have to be able to track it, investigate it, triage it. It's the eyes. It's always been like that.
So it becomes a unit economics where you can just have 100 agents, which means they need 1,000 defensive agents, and eventually you could force an organization to turn off its security- Almost like you deep dive ... because you can no longer afford it on your bank account- Yeah ... because of the token spend.
So getting that efficiency is right, and eventually organizations will have to choose anything below a certain level, we discard. Just got to let it go. But that, for a financial services organization that needs capture of events and everything through the financial, so that's going to be really tricky.
And no one has the right answer. Those are hard decisions that are going to need to be made. Unless something fundamentally changes the economics, which as we sit here today, look, if you and I knew this, we could stop working.
But I do in my heart believe that we're going to get more efficient. Right? Inference is going to be cheaper than training.
We're not going to maybe need those GPUs, some of the other chips. Something's got to give, because right now we're full speed ahead, damn the torpedoes, in terms of the economics. But that phase doesn't last forever.
No, I think it was Uber that recently came out on their talk, and they said they'd already exhausted their entire year's budget spend by April. Yeah. For their- For tokens ...
for their tokens. So something's got to give. Yeah.
Anyway, James, thank you so much. No, it's been a real pleasure. Again- I appreciate it ...
nice to see you. Good seeing you. Maybe RSA next year in April.
Fantastic. Love to. James Hadley, founder of Immersive.
com. You can check it out. We're here at KB4.